
💡 Our Technical Review in summary
Summary
Microsoft is integrating the Microsoft Purview Data Security Triage Agent into the Microsoft Defender XDR portal. This update introduces AI-generated summaries and categorizations for Data Loss Prevention (DLP) alerts, designed to streamline the investigation process and help security analysts identify the context and severity of data security incidents more rapidly.
Impact
- Enhanced Triage: Security analysts will see AI-generated insights directly within DLP alerts in the Defender XDR portal, reducing the time spent manually reviewing raw event data.
- Deployment Flexibility: If the Data Security Triage Agent is not yet active, eligible admins can initiate deployment directly from the DLP alert page in Defender XDR.
- Centralized Management: While summaries appear in Defender XDR, ongoing management tasks—such as configuring custom instructions, pausing the agent, or monitoring usage—remain centralized within the Microsoft Purview portal.
- No User Disruption: This change is strictly administrative and analytical; it does not affect end-user workflows or modify existing DLP policy enforcement.
- Timeline: Public Preview begins in early April 2026, with General Availability expected by late August 2026.
Action Required
- Enable the Agent: To utilize these features, ensure the Data Security Triage Agent is deployed within Microsoft Purview.
- Review Permissions: Verify that security analysts responsible for triaging DLP alerts have the appropriate role assignments to view AI-generated summaries in Defender XDR.
- Update SOPs: Revise internal Security Operations Center (SOC) documentation and triage workflows to include these new AI-assisted summaries.
- Training: Educate the security team on the distinction between viewing outputs in Defender XDR and performing agent configuration/management in the Purview portal.
Microsoft Official Update
Service: N/A
Category: planForChange
Severity: normal
[Introduction]
We’re introducing Data Security Triage Agent summaries and categorizations for Data Loss Prevention (DLP) alerts directly within the Microsoft Defender XDR portal. This update helps security analysts triage DLP alerts more efficiently by surfacing AI-generated summaries and categorizations created by the Microsoft Purview Data Security Triage Agent.
Screenshot 1: Data Security Triage Agent outputs and summaries now available in DLP alerts in Microsoft Defender XDR
This message is associated with Roadmap ID 558860.
[When this will happen:]
- Public Preview: We will begin rolling out early April 2026 and expect to complete by mid-April 2026.
- General Availability (Worldwide): We will begin rolling out mid-August 2026 and expect to complete by late August 2026.
[How this affects your organization:]
Who is affected:
- Security analysts and admins triaging DLP alerts in Microsoft Defender XDR
- Organizations using Microsoft Purview Data Security Triage Agent
What will happen:
- DLP alerts in Defender XDR will display AI-generated summaries and categorizations when the Agent is deployed.
- If the Agent is not deployed, eligible analysts can deploy it from the DLP alert page in Defender XDR.
- Agent management (instructions, pause/deactivate, usage monitoring) remains in Microsoft Purview.
- Existing DLP policies and enforcement are not changed.
- There is no impact to users.
Screenshot 2: Security Analysts and Admins triaging DLP alerts in Defenders will be able to deploy the Data Security Triage Agent from the Microsoft Defender XDR portal
[What you can do to prepare:]
- Deploy the Data Security Triage Agent in Microsoft Purview to enable summaries in Defender XDR.
- Review role assignments to ensure analysts who triage DLP alerts have the appropriate permissions.
- Update internal security operations documentation to reflect the new triage experience.
- Familiarize security teams with where Agent deployment can occur (Defender XDR) and where ongoing management is performed (Purview).
Learn more: Before rollout, we will update this post with new documentation.
[Compliance considerations:]
| Compliance area | Explanation |
|---|---|
| AI/ML or agent capabilities interacting with customer data | This change introduces AI-generated summaries and categorizations for DLP alerts using the Microsoft Purview Data Security Triage Agent, which processes existing DLP alert data to assist analysts during triage. |
| Admin controls | Admins can deploy the Data Security Triage Agent from the Microsoft Defender XDR portal. Ongoing agent management, including custom instructions, pausing or deactivating the agent, and monitoring usage, remains available in the Microsoft Purview portal. |
| Admin monitoring and compliance reporting | The update enhances DLP alert investigations by adding AI-generated context, improving how admins monitor and assess data security incidents without changing underlying DLP policy enforcement or audit logging. |
